Showing posts with label Week 4. Show all posts
Showing posts with label Week 4. Show all posts

Saturday, June 21, 2008

threat of online security


Thumbsucking is a huge threat that the companies face due to the proliferation of portable storage devices. As people increasingly use media players, and external hard drives for personal and business needs, each device becomes both a friend and foe to the modern-day corporation. In fact, a 2008 Applied Research-West survey found that workers born after 1980 are 200 percent more likely to have corporate data on their storage devices. This threat becomes even more prominent when devices are not company-owned or issued, but can still be used to store and transport sensitive corporate data, leaving no audit trail or trace of what's been taken. Without control, portable storage devices present four major threats to the enterprise:



  • It allows users to bypass the perimeter and introduce malware into the enterprise.
  • They allow internal users to remove confidential information such as financial files, health records, and other intellectual property from the organization.
  • Employees can bring unwanted or unauthorized programs onto the company’s network.

The biggest threat to personal data, according to Symantec, comes from the loss of laptops, hard drives, and USB drives, which accounted for 57 percent of the data loss outlined in the company's latest Internet Security Threat Report, released today. In addition, 70 percent of the malicious code unleashed in the last six months of 2007 was meant to steal confidential information. Finally, the creation of malicious software is now outpacing the creation of "good" programs. As such, all this stolen information ends up in an underground marketplace that works just like a legitimate economy.

Typical approaches to improving computer security from the threat will include the following:

  • Physically limit access to computers to only those who will not compromise security.
  • Hardware mechanisms that impose rules on computer programs, thus avoiding depending on computer programs for computer security.
  • Operating system mechanisms that impose rules on programs to avoid trusting computer programs.
  • Programming strategies to make computer programs dependable and resist subversion

In order to secure a company system, some secure systems are importance to be used like:

  1. Firewalls are systems which help protect computers and computer networks from attack and subsequent intrusion by restricting the network traffic which can pass through them, based on a set of system administrator defined rules.
  2. Anti-virus software consists of computer programs that attempt to identify, thwart and eliminate computer viruses and other malicious software (malware).
  3. Social engineering awareness keeps employees aware of the dangers of social engineering and/or having a policy in place to prevent social engineering can reduce successful breaches of the network and servers.
  4. Honey pots are computers that are either intentionally or unintentionally left vulnerable to attack by crackers. They can be used to catch crackers or fix vulnerabilities.

Friday, June 20, 2008

The application of 3th party certification program in Malaysia




Online shoppers as the third party are concern about credit card fraud, become victiom of identity theft, aware of sharing personal information on the web, and about spyware because fraud and identity theft have created a chilling effect on e-commerce. Online consumers are causing shoppers to limit spending . Most of them shop only at sites they know and trust. They have also abandoned a shopping cart because they did not “trust” the transaction.
Forrester Research found that 24% of online consumers stopped purchasing online during the 2005 holiday season due to security concerns. The growth in online commerce brings with it a significant increase in the variety of fraudulent web activities. Phishing and other scams involving fraudulent use of consumers identities online are on the rise.The reality of such figures has caused online shoppers to be wary of how they use theirpersonal information to transact business. Gaining the trust of online customers is vital for the success of e-commerce. It is necessory to increasing customer confidence at transaction time on web site to earns full potential.

Displayes of trust marks in completing online transactions become concern of online shoppers, online businesses should be sure to choose the trust mark that offers the most value. The VeriSign Secured Seal is the most trusted symbol of secure transactions on the web for this recent year and affect online shoppers decision and preference to do business with or make a purchase from a site. It's a trust mark communicate online transaction security to customers. As a result, this help to reduce the number of terminated transactions on the website.

The VeriSign Secured Seal program also delivers additional features consumers demand. One such feature is our verification functionality. When a consumer clicks on the seal, information about the VeriSign services contributing to the site's security is displayed. Much of the online shopper are interested in knowing what technology and services are behind a trust mark. Beside this, VeriSign Secured Seal is the only choice for businesses that are serious about alleviating the security concerns of online consumers. The seal is available exclusively to sites that purchase and implement VeriSign’s market-leading security solutions. Sales opportunities will also be maximize.









Tuesday, June 17, 2008

Safeguard Personal and Financial Data

Firewall Hardware
Nowadays, there is many unauthorized people attack our computer. Most common are hacker, cracker that attack a person's computer. How are we going to prevent those viruses in order to protect ourself? I would like to introuce some ways that may safeguard our personal informations and financial data.

It is so common that everyone need a software to protect own data. As a result, an individual should maintain an antivirus sofware and firewall to protect personal and financial data. How an antivirus work in order to protect our personal and financial data? It helps to prevent any unauthorized person steal a private and confidential information. For instance: name, address, bank account number.

Firewall hardware can protects an outside hackers access to a personal computer. Firewall hardware is firewall network used by many people to protect unauthorized access. Firewall hardware set up between a computer and DSL modem which protects a single and multiple computer. An individual should regularly scan their own computer to prevent spyware. It may affect a perfomance of one person's computer which hackers access your personal data. An individual should used password and encrypting files to protect themselves. This ensure that unauthorized people access and view your data. Full disc encrypting which prevents thief from turn on other's person computer without passphrase.


AVG Anti-spyware protection package


I have came across one policy on safeguarding personal informations and financial data. The policy named "University Confidentiality" which stores private informations and financial data. All the universiti students and staffs safeguarded under this policy such as loan paid to students. Students private and confidential informations are to be safeguarded to prevent any unauthorized access. Some other people may view your financial data like steal your bank password or credit card number for illegal purposes. For instance, get credit card numbers to apply loan. As a result, we need the policy in order to protect ourselves get cheated.

Well, what are the steps taken by Florida State University to safeguard personal data of students and staffs? The University policy will designate more employees coordinate safeguarding. All the staffs must be coordinate to safeguard their private informations and financial data. It will evaluate the effectiveness of the safeguarding to make sure that it in line with its clients protection. "Confidentiality Policy" recognized the importance of protecting unauthorized access, miuse, loss information resources. All printed material containing confidential, personal information related to financial transactions, including name, birth date, address, telephone number, social security number, personal photograph, amounts paid or account number, are to be safeguarded. There is only authorized employees may view a document stored in University information system. The sytem which directly linked to a specific account that just authorized person may review, scan, print and store paper document and correspondence electronic files directly on computer system for immediate backup and retrival.
These are all the safeguard that I have had came across through internet. Anyone who is interested kindly log on to http://www.fsu.edu.com/ for detail informations.

Phishing: Examples and Safeguards

So want to earn some easy money? Fishing is the way to go or it is phishing. With millions of people using the internet to do online transactions, many are unawared that some unscrupulous people had taken the advantage to conned this people for their financial gains.

In computing, phishing is an attempt to criminally and fraudulently acquire sensitive information, such as usernames, passwords and credit card details, by masquerading as a trustworthy entity in an electronic communication. Phishing is an example of social engineering techniques used to fool users.

It is an act of sending an e-mail to a user falsely claiming to be an established legitimate enterprise in an attempt to scam the user into surrendering private information that will be used for identity theft. The e-mail directs the user to visit a Web site where they are asked to update personal information, such as passwords and credit card, social security, and bank account numbers, that the legitimate organization already has. The Web site, however, is bogus and set up only to steal the user’s information.

Phishing is also referred to as brand spoofing or carding, is a variation on "fishing," the idea being that bait is thrown out with the hopes that while most will ignore the bait, some will be tempted into biting.

An image showing how phishing works

Most phishing cases that i stumbled across while searching are normally financial institutions are being targetted where many fake e-mails had been sent to their customers to trick them into entering their personal information to gain access to their bank accounts. Here are some e-mails which found to be fake taken from the original website of the banks in Malaysia telling their customers to be more cautious.

1)Maybank:

http://www.maybank2u.com.my/online_security_watch/phishing_web_site.shtml#

2)PublicBank:

http://www.pbebank.com/en/en_content/info/phishing.html

For the past 20 years of my life, i have never been trick into submitting my personal details to fake e-mails because i do not really use the internet for any business transactions or anything that involves money. I am also skeptical about online transactions because of cases like phishing and other online threats, i do not feel safe using the internet for now maybe until i feel that there are adequate protection to prevent phishing.


The methods and safeguards that can be use to avoid be a victim to phishing would be:


1)If you get an email or pop-up message that asks for personal or financial information, do not reply. Legitimate companies don’t ask for this information via email.


2)Use anti-virus and anti-spyware software, as well as a firewall, and update them all regularly. Some phishing emails contain software that can harm your computer or track your activities on the Internet without your knowledge.

Above are just a few methods to prevent phishing. Below are some websites which tell us how to avoid be a victim to phishing:

Chuang Computer Tips:

Tips on how to improve your computer performance, problems, security and many more.

1)http://www.chuangcomputer.com/blog/2007/08/secret-tips-to-prevent-phishing-attack.html

Internet Fraud Tips from the National Consumers League's Internet Fraud Watch

2)http://www.fraud.org/tips/internet/phishing.htm

Well there more to phishing but i am going to stop here. Last words, just be extra cautious and alert.